UK Supreme Court Ruling Sets Global Precedent: Cross-Border Spyware Deployment Does Not Qualify for Sovereign Immunity

The UK Supreme Court has ruled that the Kingdom of Bahrain cannot claim sovereign immunity in a lawsuit alleging state use of spyware against UK-based dissidents, establishing that remote cyber operations launched from abroad can be treated as acts committed within the victim's own territory.

Layla Haddad
Cyber Policy & Digital Risk Correspondent5 min read
Courtroom interior representing legal ruling on state immunity in cross-border spyware case

Courtroom interior representing legal ruling on state immunity in cross-border spyware case

The UK's Supreme Court has ruled that the Kingdom of Bahrain cannot claim sovereign immunity against legal action brought by two UK-based dissidents who allege they were targeted with spyware, in a judgment expected to open the way for further litigation against states that deploy surveillance technology against individuals living in the UK.

The case, Kingdom of Bahrain v Shehabi and another, was brought by Saeed Shehabi and Moosa Mohammed, who allege their computers were infected with FinSpy spyware, developed by Gamma Group, while they were living in London in 2011. According to court filings, the alleged intrusion enabled the collection of messages, emails, calendar records, contact lists, browsing history, photographs, documents and video from the claimants' devices, along with the ability to track device location and covertly activate microphones and cameras.

The legal mechanism at the centre of the ruling

Bahrain's defence rested on the State Immunity Act 1978, arguing that sovereign states are entitled to immunity in cases where the individuals or acts causing personal injury are not physically located in the UK. Bahrain's position was that a remote cyber operation, initiated from outside UK territory, should not be treated as an act occurring within the jurisdiction for the purposes of the Act.

The Supreme Court rejected that argument by a 3 to 2 majority. Lord Lloyd-Jones, Lord Hamblen and Lady Simler found in favour of the claimants, while Lord Leggatt and Lord Burrows issued dissenting opinions. The majority held that modern surveillance technology allows intrusion to be carried out entirely remotely, and that even where a foreign state conducts such an operation from outside the UK, the act itself constitutes an infringement of UK territorial sovereignty. In practical terms, the ruling establishes that the location of the server or operator initiating a cyberattack is not determinative of jurisdiction; what matters is the location of the device and person actually affected. That distinction, between where an attack originates and where its effects land, is the same jurisdictional logic increasingly shaping how state-sponsored network infrastructure compromise is analysed and attributed, regardless of where the underlying hardware or command infrastructure physically sits.

How the alleged intrusion came to light

According to the claimants, the alleged hacking was not discovered until 2014, when documents published by WikiLeaks detailing Bahrain's use of FinSpy became public, and a research and advocacy organisation subsequently identified Shehabi and Mohammed as affected individuals. Shehabi has lived in the UK since 1973 and holds British citizenship; Mohammed arrived in the UK as a refugee in 2006 and has since been granted indefinite leave to remain.

Following the ruling, the claimants' solicitor said the decision sends a clear message to states that deploy intrusive surveillance technology against political activists and others residing abroad, and is expected to open the door to further legal action by individuals in similar circumstances. The law firm representing the claimants noted it has separately represented individuals in cases involving spyware allegedly linked to Rwanda, Saudi Arabia and Pakistan, indicating this ruling's relevance extends well beyond this single case.

Bahrain has consistently denied the allegations throughout the proceedings, maintaining since the case was first filed at the High Court in 2020 that it did not hack Shehabi and Mohammed's laptops. Bahrain's immunity claim was first rejected by the High Court in 2023, upheld again by the Court of Appeal the following year, and has now been dismissed a third time by the Supreme Court, though the underlying question of whether the alleged hacking actually took place has not yet been determined and will now proceed to trial.

Part of a broader pattern of spyware litigation in UK courts

This ruling does not stand alone. UK courts have handled a series of related cases in recent periods, including a judgment ordering Saudi Arabia to pay damages to a London-based activist over allegations involving Pegasus spyware, a separate case permitting legal action against Bahrain over allegations involving Pegasus spyware deployed against a UK-based blogger, and a case permitting a pro-democracy campaigner to pursue legal action against Saudi Arabia over allegations involving Pegasus and QuaDream spyware. Separately, the UK and France have hosted diplomatic discussions aimed at building international agreement on curbing the proliferation of commercial spyware and so-called hacker-for-hire services.

Why this matters for enterprises and governments across the GCC

For any government or state-linked entity in the Gulf procuring or operating commercial surveillance and spyware capability, this ruling narrows the legal protection previously assumed to apply when such technology is deployed against individuals residing in jurisdictions like the UK. Sovereign immunity claims tied specifically to the physical location of the operator or server are no longer a reliable shield once a device and person actually affected are located within a court's jurisdiction.

For enterprises operating in or with the Gulf, particularly those in legal, compliance, and technology sectors advising government or state-linked clients, this ruling is a relevant data point for risk assessment around the use of commercial offensive security and surveillance tooling. Vendors supplying spyware or surveillance capability to state clients, and the state clients themselves, face a legal environment in Western courts that is becoming measurably less permissive toward jurisdictional immunity defences, a trend consistent with the broader pattern of related litigation UK courts have handled against multiple governments in the region over recent periods. It also reinforces a wider compliance reality already shaping how GCC organisations approach cybersecurity governance: frameworks such as the UAE's NESA cybersecurity guidelines are built around the explicit assumption that state-sponsored attacks targeting regional infrastructure are a standing, documented threat category, rather than a hypothetical risk confined to unusually high-profile targets.

Layla Haddad

Cyber Policy & Digital Risk Correspondent

Layla Haddad covers cybersecurity regulations, data protection laws, and digital transformation initiatives across GCC and North Africa. She has worked closely with compliance teams, fintech startups, and government advisory groups. Her articles explore how cyber policy, AI governance, and privacy frameworks shape the region’s digital future.

Intelligence Focus Areas

state-sponsored spyware litigationcyber jurisdiction and sovereign immunitycommercial surveillance governance